HelloZeroNet / HelloZeroNet/ZeroNet
Ability to login via Multiuser plugin easily over Websocket
- Dominant language
- JavaScript
- Stars
- 18.8k
- Forks
- 2.3k
- PR merge metrics
- No merged PRs in 30d
Description
Currently the Multiuser plugin's API is quite browser-specific. From reverse-engineering how it works, I've discovered that to login via Multiuser you must:
* you login by calling "userLoginForm" and receiving a prompt containing HTML
* ignore the HTML and respond to the prompt with a private key
* the plugin converts this private key to a master_seed and a master_address
* the plugin creates some javascript to load the master_address into your browser's cookies
* it sends that javascript back to you
* now on subsequent requests you're supposed to send the master_address as a cookie (called "master_address")
This isn't too complicated (though extracting the master_address from the returned JS is a little horrible), but the real problem comes in when some WebSocket clients don't support setting cookies.
Is it possible to have a different method of authenticating one's requests to Multiuser? I agree cookies are quite elegant, and keep the request payload clean, but it makes things tricky for non-browser clients.
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reviewing the Multiuser plugin flow described here, especially userLoginForm, the returned JavaScript, master_address cookies, and the WebSocket client constraint. Define an alternative request-authentication method that works for clients unable to set cookies, then verify that subsequent Multiuser requests can authenticate without browser-specific cookie handling.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- api, authentication
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100